TF-MAL-elf.bqtlock
📛 Threat Title
Malware family: BQTlock
Description
ThreatFox malware family `elf.bqtlock`. Printable name: BQTlock.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.bqtlock
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bqtlock
IOC database
- Type
- domain
- Value
elf.bqtlock- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.bqtlock
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bqtlock
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Explore how BQTLock and GREENBLOOD ransomware operate, why they threaten businesses, and how ANY.RUN helps detect attacks earlier.
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as BQTLock .
-
web:cyberpress.org
Incident Response: Establish clear response protocols for ransomware attacks. Quick containment and remediation can limit downtime and reduce the financial impact of an attack. BQTLock and GREENBLOOD highlight the increasing sophistication of ransomware attacks, where speed, stealth, and data exfiltration are used to amplify damage.
-
web:cybersecuritynews.com
A sophisticated new ransomware strain named BQTLOCK has emerged in the cyberthreat landscape since mid-July 2025, operating under a comprehensive Ransomware-as-a-Service (RaaS) model that democratizes access to advanced encryption capabilities for cybercriminals. The malware , associated with 'ZerodayX', the alleged leader of the pro-Palestinian hacktivist group Liwaa Mohammed, represents a ...
-
web:medium.com
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration ...
-
web:redpiranha.net
Updated Malware Signatures (Week 1 - January 2026) ... BQTLock Ransomware BQTLock is a ransomware family that emerged in mid-2025 and operates as a Ransomware-as-a-Service (RaaS) platform. It uses hybrid encryption, combining AES-256 for files with RSA-4096 for key protection, and appends the ". bqtlock " extension to encrypted files.
-
web:socradar.io
A ransomware family with no name—until now. This white paper provides the first comprehensive analysis of BQTLock , an emerging ransomware operation that's been active since early 2024 but remained off the radar due to its evasive tactics and lack of branding.
-
web:www.cyfirma.com
Deploy a unified threat management strategy - including malware detection, deep learning neural networks, and anti-exploit technology - combined with vulnerability and risk mitigation processes.
-
web:www.pcrisk.com
What kind of malware is BQTLOCK ? BQTLOCK is ransomware designed to prevent victims from accessing/using their files by encrypting them. In addition to locking data, the ransomware appends its extension (". BQTLOCK ") to files and provides a ransom note (" READ_ME-NOW_2526968.txt "). Here is an example of how BQTLOCK renames files: it changes " 1.jpg " to " 1.jpg. BQTLOCK ", " 2.png " to " 2.png ...
-
web:www.ransomlook.io
BQTLock surfaced in July 2025 and operates as a fully-fledged Ransomware-as-a-Service (RaaS) with a double-extortion model. It employs AES-256 for file encryption, with keys secured by RSA-4096, appending the . BQTLOCK extension to encrypted files.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.